Almost every business I walk into has already deployed AI. Nobody signed anything off, no budget was approved, and the board has not discussed it. It happened because somebody in accounts pasted a supplier contract into a chatbot to get the gist of it, it worked, and they told two colleagues. That is AI deployment. It is just deployment without governance, which is the part that decides whether it turns out to be the best thing you did this year or the thing your insurer asks about.
AI governance is the set of frameworks and organisational rules that make AI deployment responsible. Stripped of the consultancy language, a working framework answers five questions in writing:
Which tools are approved? What data may go into them? Which decisions must a human still make? Who signs off something new? And how would you prove any of the above six months later? Answer those five and you have governance. Leave them unanswered and you have hope.
I want to be blunt about something first, because it shapes everything that follows. Governance is not there to slow your team down. Nine times out of ten the businesses with written AI rules are using AI far more aggressively than the ones without, precisely because their people are not quietly guessing where the line is. Uncertainty is what makes staff timid. Clarity is what makes them fast.
What AI governance actually means
Governance is an organisational discipline, not a technical one. It sits above the tools. You could swap ChatGPT for Claude tomorrow and your governance framework should barely change, because it is about decisions, ownership and evidence rather than which vendor you happen to be paying.
Three layers are worth separating in your head, because people muddle them constantly and then wonder why the document they wrote does not work:
| Layer | What it is | Who reads it |
|---|---|---|
| Framework | The structure: who owns AI decisions, how tools get approved, how risk is assessed and recorded, when it is reviewed. | The board, or whoever functions as one. |
| Policy | The rules themselves: approved tools, permitted uses, the data red line, what needs a human check. | Every member of staff. |
| Practice | What people actually do at their desks: prompts, habits, verification, escalation. | Individual teams, day to day. |
Most organisations attempt the middle layer, write two vague pages about using AI responsibly, and skip the layers either side. The framework is missing, so nobody owns it. The practice is missing, so nobody knows what the rules mean on a Tuesday afternoon with a deadline at four. The policy then sits on the intranet being technically true and practically ignored.
Why UK businesses need this now
The UK has no single AI Act. Rather than one statute, the approach set out in the government’s pro-innovation white paper hands AI oversight to the regulators who already cover your sector, working to a set of cross-cutting principles: safety and robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress.
That sounds gentle until you realise what it means in practice. There is no new AI regulator to wait for. The obligations you already have simply extend to cover the way you use AI:
- UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, apply the moment personal data touches an AI tool. Lawful basis, purpose limitation, data minimisation, transparency and the rules around automated decision-making all still apply. The ICO has published detailed guidance on AI and data protection, and a Data Protection Impact Assessment is likely to be required where the processing is high risk.
- Your sector regulator already expects competence and supervision. The SRA, FCA, ICAEW, RICS and the rest have not carved out an exception for work that a model helped with. If AI drafted it and you sent it, you own it.
- Employment and equality law bites hard on recruitment and performance tools. A screening process that quietly disadvantages a protected group is unlawful whether a person or a model produced the ranking.
- The EU AI Act has extraterritorial reach. If you place an AI system on the EU market, or the output of your AI system is used in the EU, you can be in scope with no EU office at all. Obligations are phased, and the timetable has been subject to proposed amendment, so check the current position rather than trusting a date you read somewhere.
- Your clients are the fastest-moving regulator of all. Supplier questionnaires now routinely ask whether you have an AI policy, whether client data enters public models, and who is accountable. I have watched businesses lose tenders on that one question.
If you want a standard to anchor to, ISO/IEC 42001 is the AI management system standard, and it maps well onto ISO 9001 or 27001 if you already run either. You do not need to certify. Borrowing the structure is enough for most businesses.
The five decisions a governance framework must make
Here is the whole thing. Five decisions. Everything else is elaboration.
Which tools are approved
Name them. Not categories, not ‘reputable enterprise AI tools’. Actual names, actual tiers. There is a real difference between a consumer account and a business tier with a data processing agreement and training switched off, and your staff cannot be expected to know which one they signed up to.
- List approved tools by name and by tier.
- List what is explicitly not approved, including the browser extensions and the free note-taking bots that quietly join meetings.
- Say what happens when somebody wants something new, and make that route easy or they will simply not use it.
Where the data red line sits
This is the single most useful sentence in any AI policy, and it must be short enough to recite. Something a new starter can hold in their head on day one, such as: nothing that identifies a client, a patient or an employee goes into any tool outside this list, ever.
- Be specific about the categories that matter in your business: personal data, special category data, client confidential material, commercially sensitive terms, drawings and IP, unpublished financials.
- Explain anonymisation properly, including that a postcode plus a job title is often not anonymous at all.
- Give people a sanctioned alternative for the thing they wanted to do, otherwise the red line becomes a dare.
Which decisions stay human
AI can draft anything. It should decide almost nothing. Write down the decisions that always require a named person: hiring and firing, credit and pricing, clinical or legal advice, anything affecting an individual’s rights, anything that goes out under a professional signature.
- Distinguish AI-assisted from AI-decided, and put the second category on a short leash.
- Set the verification standard: what must be checked, against what source, by whom.
- Remember that a human who rubber-stamps output is not meaningful oversight, and would not be treated as such if challenged.
Who owns it
One name, at senior level, with the authority to say no. In a business under fifty people that is usually the managing director, the finance director or the operations lead, because most AI questions turn out to be commercial and reputational rather than technical. Delegating the whole thing to IT is the most common structural mistake I see.
- Name the owner and name a deputy for when they are on holiday.
- Name gatekeepers per department who triage requests before they escalate.
- Put a review date in the diary. Quarterly to start with, because this field moves.
How you would prove it
Governance you cannot evidence is an opinion. You need a modest paper trail: the policy with a version and date, the approved tool list, a record of who was trained and when, a short risk note for anything material, and a log of decisions to approve or refuse a tool.
- Keep it proportionate. A spreadsheet and a folder beats a platform nobody updates.
- Record refusals as well as approvals. They are the most persuasive evidence that the process is real.
- Make training attendance part of the record, because competence is the defence you will actually want.
Governance is not the brake. It is the thing that lets you take your foot off it.
How to write it in a day
You do not need a consultancy and a twelve-week programme. You need the right eight people in a room for a day and a facilitator who will not let the conversation drift into philosophy. This is the order that works:
- Find out what is already happening. Anonymous, no blame, genuine amnesty. Ask what tools people are using and what they are putting into them. This is always the most revealing hour of the day, and it is where the real risks surface rather than the imagined ones.
- Sort the uses into three buckets. Fine, fine with conditions, and never. Do it with real examples from step one, not hypotheticals.
- Draw the data red line and write it in one sentence.
- Set the tool list and the route for requesting additions.
- Write the rules by department. Finance, sales, HR and operations have genuinely different exposure, and one flat page for everybody is why most policies fail.
- Name the owner, the deputy and the gatekeepers.
- Set the review date and agree what would trigger an earlier review.
That is a day’s work and you finish holding the document, not a promise of one. That is exactly what our AI Policy Workshop is: a full day for up to ten people that produces your own written policy in your own language, rather than a template with your logo on it.
The mistakes I see most often
Downloading a template
A generic AI policy is worse than none, because it creates a paper record of rules nobody follows. The value is not in the document. It is in the argument your leadership team has while writing it, which is where you discover that finance and sales have completely different ideas about what counts as confidential.
Banning it
Prohibition produces shadow AI. People use their personal accounts on their personal phones, and you lose the one thing you had, which was visibility. A ban is not a governance framework. It is an abdication with a stern tone of voice.
Writing rules nobody can apply
‘Use AI responsibly and in line with company values’ is not a rule. It is a sentiment. If a member of staff cannot use your policy to decide whether to paste a particular email into a particular tool, it has not told them anything.
Treating it as a one-off
Tools change monthly. A policy without a review date is a snapshot of what you believed in a specific quarter. Put the date in the diary before you leave the room.
Separating governance from training
This is the one that costs the most. Rules without skills produce staff who are compliant and useless. Skills without rules produce staff who are productive and exposed. You need both taught together, which is why our sessions cover the practical work and the policy in the same programme.
What good governance looks like in practice
You can tell within about ten minutes of walking into a business whether the governance is real. Not by reading the document. By asking three people the same question.
Ask them which AI tools they are allowed to use. In a business with working governance, three people give the same answer without checking. Ask them what they must never put into one. Same again, roughly the same sentence, because they were taught it rather than sent it. Ask who they would go to about a new tool. They name a person, not a department.
That is the whole test. It has nothing to do with the length of your policy and everything to do with whether it was built with the people who have to live inside it. The Oxford AI School is the best place to learn AI skills to optimise your business through AI in the UK, and a large part of the reason is that we refuse to treat governance and capability as separate purchases. They are the same conversation.
Frequently asked questions
What is AI governance?
AI governance is the set of frameworks, organisational rules and accountability structures that decide how a business deploys AI responsibly. In practice it answers five questions in writing: which tools are approved, what data may go into them, which decisions a person must still make, who signs off new tools, and how you would prove any of that after the fact. It is an organisational discipline rather than a technical one, which is why it belongs with the board and not only with IT.
Is AI governance a legal requirement in the UK?
There is no single UK AI Act. Existing law applies through existing regulators instead. UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, govern personal data used in AI, and sector regulators apply their own rules on competence and supervision. So AI governance is not a standalone legal duty, but the duties it discharges are legally binding and already apply to you.
What is the difference between an AI policy and an AI governance framework?
The policy is the document your staff read: what they may and may not do. The framework is the structure around it: who owns the policy, how tools get approved, how risk is recorded, how often it is reviewed and who is accountable when something goes wrong. The policy is one output of the framework rather than a substitute for it.
Who should own AI governance in a small business?
One named person at senior level with the authority to say no. Usually the managing director, finance director or operations lead rather than an IT manager, because most AI decisions are commercial and reputational rather than technical. Write the name down, and make sure that person actually reviews requests.
Does the EU AI Act apply to UK companies?
It can. The Act has extraterritorial reach, so a UK business placing an AI system on the EU market, or whose AI output is used in the EU, may be in scope without any EU establishment. Obligations are phased and the timetable has been subject to proposed amendment, so verify the current position rather than relying on a remembered date. For most UK small businesses using ordinary AI assistants internally, UK GDPR and sector regulation are the more immediate concern.
How long does it take to put AI governance in place?
For a small or mid-sized business, a working first version takes about a day. Our full-day AI Policy Workshop for up to ten people produces a written AI acceptable use policy, an approved tool list, a data red line, rules by department, named gatekeepers and a review date. Larger or regulated organisations then layer formal risk assessment and audit on top of that base.
Do we need AI governance if we only use ChatGPT for emails?
Yes, and it will take you an afternoon rather than a day. The exposure is not proportional to how sophisticated your use is. It is proportional to what your staff paste in, and people paste in remarkable things when nobody has told them not to.
Harry Lang is the founder of The Oxford AI School. We help business owners, directors and teams across the UK learn to use AI properly, and to write the rules that let them do it without losing sleep.
If your business is using AI and nobody has written down the rules, that is the gap worth closing this month. See the AI Policy Workshop, or book a free 10-minute intro call and we will tell you honestly whether you need a day or an afternoon.